Law / Frameworks / NIST AI RMF / Measure

NIST AI RMF, MeasureMEASURE 2.11

Fairness and bias – as identified in the MAP function – are evaluated and results are documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.11

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

13
laws
10
places
0
with court rulings behind them
3
not yet in force
1
proposed, not law

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alabama
  • Colorado
  • European Union
  • Illinois
  • Kazakhstan
  • Maryland
  • New Jersey
  • New York
  • Qatar

AI risk obligations

6 laws, 5 places
PlaceLawWhat it asks, as read here
European Union AI Act, Article 10 (data and data governance) from , in 14 months

Apply data governance and management practices appropriate to the system's intended purpose, covering your design choices; how you collected the data and, for personal data, why you originally collected it; your data-preparation operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation; the assumptions you made about what the data measures and represents; an assessment of whether the data sets you need are available, sufficient in quantity, and suitable; examination of the data for biases likely to affect health and safety, harm fundamental rights, or lead to discrimination prohibited under Union law, especially where one operation's data outputs become a later operation's inputs; and measures to detect, prevent and mitigate any bias you find.

European Union AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months

If your high-risk AI system continues to learn after it is placed on the market or put into service, develop it to eliminate or reduce as far as possible the risk of biased outputs feeding back into future operations, and put mitigation measures in place for any feedback loop that remains.

Maryland HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review

Ensure the tool is fairly and equitably applied and does not result in unfair discrimination or directly or indirectly cause harm to an enrollee.

New Jersey New Jersey Disparate Impact Discrimination Rules, Automated Employment Decision Tools

If you provide or deploy an automated employment decision tool for use on New Jersey applicants or employees, including a tool that scores, ranks, or classifies candidates or that assesses schedule availability, adequately test it before use to confirm it does not adversely affect a protected class.

New York New York Artificial Intelligence Act proposed

Conduct regular impact assessments of the high-risk AI system for algorithmic discrimination.

New York City Automated Employment Decision Tools Bias Audit and Notice Law

Before screening a candidate or employee in New York City with an automated employment decision tool, a product must be the subject of a bias audit performed within the prior year, publish a summary of that audit, and notify each affected candidate or employee at least ten business days beforehand of the tool's use and the job qualifications and characteristics it assesses.

AI sector rules

5 laws, 4 places
PlaceLawWhat it asks, as read here
Alabama SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days

Certify annually to the Alabama Department of Insurance that the artificial intelligence does not rely on a group dataset, is applied fairly and equitably consistent with applicable federal guidance, and does not discriminate against any subscriber group or enrollee.

Colorado Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models

Establish a documented, risk-based governance and risk management framework, including a cross-functional governance group drawing on legal, compliance, risk management, product development, underwriting, actuarial, data science, marketing, and customer service, designed to determine through quantitative testing whether your use of an external consumer data and information source, or an algorithm or predictive model that uses one, results in unfair discrimination with respect to race, and to remediate any discrimination detected.

Colorado SB 21-169 (2021), Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models

Do not unfairly discriminate based on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression, in any insurance practice.

Where the Commissioner of Insurance has adopted implementing rules for your type of insurance and practice, do not use an external consumer data and information source, or an algorithm or predictive model that uses one, in a way that unfairly discriminates on those same grounds.

Illinois Illinois Human Rights Act, use of artificial intelligence in employment decisions

Do not use artificial intelligence in a way that has the effect of subjecting an employee or applicant to discrimination on the basis of a protected class, and do not use a zip code as a proxy for a protected class, in recruitment, hiring, promotion, discipline, discharge, or the terms and conditions of employment.

Qatar Qatar Central Bank Artificial Intelligence Guideline

A QCB-regulated entity deploying a High-Risk AI system must maintain an AI system register, adopt an AI governance policy, conduct risk and bias assessments, and provide human oversight of the system's decisions.

AI governance

1 law, 1 place
PlaceLawWhat it asks, as read here
European Union AI Act, Article 4a (processing of special categories of personal data for bias detection and correction)

If you are a provider of a high-risk AI system, you may exceptionally process special categories of personal data to the extent strictly necessary to detect and correct bias under Article 10(2), points (f) and (g), provided all six conditions of Article 4a(1) are met: the bias cannot be effectively addressed with other data, including synthetic or anonymised data; the data is subject to technical re-use limits and state-of-the-art security, including pseudonymisation; the data is secured with strict access controls and documented access; the data is not transmitted, transferred, or otherwise accessed by other parties; the data is deleted once the bias is corrected or its own retention period ends, whichever comes first; and your records of processing activities under the GDPR, the EU institutions data protection regulation, or the law enforcement directive state why the processing was strictly necessary and why other data could not achieve the same result.

AI transparency

1 law, 1 place
PlaceLawWhat it asks, as read here
Kazakhstan Digital Code, algorithmic decision-making rights

Do not let a decision made using an algorithmic system result in discrimination on a ground Kazakhstani law sets out.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.